Group:
Clop
Discovered by ransomware.live: 2025-01-24
Estimated attack date:
2025-01-24
Country:
Description:
[AI generated] CPS.EDU refers to Chicago Public Schools (CPS), one of the largest public school districts in the U.S., serving over 355,000 students in 642 schools. It provides comprehensive educational programs, including traditional, magnet, charter, and special education for students from preschool through high school. The district also offers programs for English language learners and special needs students. CPS is committed to improving public education and preparing students for their future.
Infostealer activity detected by HudsonRock
Compromised Employees: 194
Compromised Users: 2724
Third Party Employee Credentials: 1574
External Attack Surface:
129
DNS Records:
The following DNS records were found for the victim's domain.
- usb-smtp-inbound-1.mimecast.com.
- usb-smtp-inbound-2.mimecast.com.
- cisco-ci-domain-verification=2afeedffee74f590f3d4ad0a95128c8bce442aa6824bfb0e0d706b1765547ebf
- docusign=fde12f64-7579-455b-b917-325a570cb9ca
- e2ma-verification=t50bb
- sending_domain954043=a0ceb4f6e917798e0e812ae02babf2724be4c366419b63f6dd5cfa05b6c37f3a
- MS=AF213F747950198B36CEB225645512C1FFAA7F97
- duo_sso_verification=p1iT8zKhJnQWRckpBhE7B3X8HFjo5BcKVxLPNOPSEzY4vKJKGtFjGH9VTC1aQkf2
- adobe-idp-site-verification=0f6ce28e3442488a0e3275fc5e6707980e66f8485928a917678a9a3edea2eb62
- docusign=763ca110-98ab-4955-9c91-023f2157292e
- airtable-verification=7cd312f2fa2f45b985fadcd983c9f2ea
- MS=ms48801062
- v=spf1 include:_g1.cps.edu a:b.spf.service-now.com include:_a.cps.edu include:rp.oracleemaildelivery.com include:_spf.salesforce.com include:spf_c.oraclecloud.com ~all
- google-site-verification=XfdQRzQLIGdOZCVQVWAzYpR2-4nJOmxZenEsTZ4xjlc
Cloud / SaaS Services Detected
Adobe
Microsoft 365
Salesforce
Oracle Cloud
Cisco
Cisco Duo
Mimecast
DocuSign
ServiceNow
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.